💻
Hackers sent scam emails from Meta's own address by abusing its business platform
💻 Technology

Hackers sent scam emails from Meta's own address by abusing its business platform

Security firm Huntress uncovered a phishing campaign in which hackers abused Meta's business account email infrastructure to send scam messages that appeared to come from Meta itself. Victims were tricked into surrendering login credentials, which attackers exfiltrated to Telegram for account takeover and scam ads. Meta has since added guardrails that stopped the campaign, and Huntress published indicators of compromise to help organisations detect related activity.

Comments

No comments yet